Europe checks the mail. Nobody stops it.

HostingBrain analyst brief · July 2026 · data snapshot 2026-08-18 · aggregate-level, no named providers

Email security surveys love one number: SPF adoption. By that number, Europe looks done — of the 18,804,722 mail-carrying, active domains we observe, 81.9% publish an SPF record. Compliance checklists get ticked. Deliverability consultants move on.

But an SPF record is a sentence, and the sentence has an ending. It either ends in -all"reject mail that fails" — or in ~all"flag it, deliver it anyway, someone else's problem." Measured on live DNS, only 29.4% of Europe's mail-carrying domains publish the reject ending. 47.3% publish soft-fail: the spoofed mail still arrives, wearing a warning label most mail clients never show.

Adoption is a solved problem. Enforcement is not. Half of Europe's business mailboxes are protected by a policy that asks spoofed mail to feel bad about itself.

The league table inverts when you measure enforcement

Per market, the two numbers tell opposite stories. Italy publishes SPF on 88.8% of its mail-carrying domains and rejects on 22.1% — the second-weakest enforcement on this chart, and roughly one publisher in four. Denmark and Sweden publish least (67.8% and 69.6%) but their publishers enforce at the highest rates on the continent — Sweden rejects on 40.4% of all its mail-carrying domains, nearly three in five of the ones that publish anything. Poland leads both axes.

% of mail-carrying business domains: SPF published (light) vs reject-on-fail enforced (solid) Poland96.2 / 53.4 Austria85.5 / 42.1 Sweden69.6 / 40.4 Switzerland90.4 / 40.3 Denmark67.8 / 38.0 France89.7 / 32.6 Netherlands87.3 / 30.4 UK76.2 / 30.3 Norway79.6 / 28.7 Spain92.7 / 24.7 Italy88.8 / 22.1 Germany76.7 / 20.1 Europe81.9 / 29.4 solid = SPF ending in -all (reject) · light = any SPF record Source: HostingBrain · hostingbrain.ai · as of 2026-08-18

Why the gap exists — and why it persists

Soft-fail is the safe default of the entire onboarding chain. Hosting panels generate ~all so a customer's newsletter never bounces during setup. Consultants recommend ~all "for the transition" — and the transition never ends, because nothing breaks. That is exactly the problem: a policy that never breaks anything also never blocks anything.

The countries that enforce are instructive. Poland's 53.4% and Sweden's publisher-enforcement rate don't come from stricter businesses — they come from national provider defaults and registrar practice. Email enforcement is an infrastructure-supply property before it is a customer-demand property. Which is also the commercial point: the operator who flips their default moves their whole book up this chart.

Why this costs money now — not someday

The receivers already flipped the switch. Since 2024, Google and Yahoo reject or junk bulk mail that fails authentication — the era of "flag it and deliver anyway" is ending on the receiving side regardless of what senders publish. A hosting book full of soft-fail customers is a book whose newsletters and invoices are drifting toward spam folders: deliverability incidents, support tickets, and churn that lands on the operator's P&L, not the customer's security budget.

Spoofing is the loss line, not the hypothetical. Business email compromise — the fraud that weak enforcement invites — is consistently among the largest cyber-loss categories insurers pay out. A domain publishing ~all is a domain any attacker can impersonate with mail that most receivers still deliver. For insurers and lenders, the enforcement share of a book is an underwritable, portfolio-level risk number; adoption percentages are not (everyone's is ~80%).

For hosting operators, this is a rare differentiator that isn't price. Enforcement is an infrastructure-supply property — the operator who ships reject-on-fail defaults plus DMARC setup and authentication monitoring moves the whole book up this chart, cuts their own deliverability support load, and sells protection into a base that increasingly has to buy it anyway. We benchmark posture per operator book, so the gap to peers is a number, not a pitch.

Method & honesty. Measured on mail-carrying, active domains (operating MX; parking and monetization MX excluded; dead pages excluded) — 18,804,722 in Europe, 106,067,185 globally (global: 81.4% SPF, 21.0% hard-fail; Europe is ahead of the world on enforcement). "Enforcement" = SPF policy ending -all; soft-fail ~all = 47.3% of Europe's mail-carrying domains. DMARC, now measured. Earlier versions of this brief said DMARC adoption was not yet collected. It is — read from _dmarc.<domain>, not from the apex — and it widens the enforcement gap rather than closing it: 49.8% of Europe's mail-carrying domains publish a DMARC record, but only 9.4% publish a reject policy. The rest monitor or quarantine, which is the same "flag it, deliver it" posture one layer up. Separately, 58,430 European domains carry a DMARC record misplaced at the apex instead of _dmarc — a misconfiguration tally, not adoption, and it is added to neither figure. Domain-level, aggregate-only; per-operator posture lives in the product.

Reproduce this — or ask it yourself

Every figure here is queryable through the HostingBrain connector. In Claude or any MCP-compatible assistant, this is the whole brief in one prompt:

Prompt · paste into an MCP client with HostingBrain connected

“Using HostingBrain, compare SPF adoption versus SPF hard-fail enforcement across European markets — Europe overall, then Poland, Italy, Sweden and Germany. Which markets publish but don't enforce?”

Resolves to email_security (free). See definitions('spf_posture').

Reproduce this analysis: the email_security tool returns adoption, hard-fail and soft-fail shares for every market above — free tier. Per-operator posture: email_security(operator=...) (Pro).

Ask the follow-up yourself. HostingBrain answers questions like this — with the date, denominator and caveats attached — inside Claude and any MCP-compatible assistant.

Get free access

Share this pageShare on LinkedIn